Affiliation:
1. College of Computer Science and Software Engineering, Shenzhen University, Shenzhen, China
2. School of Computing, Engineering and Digital Technologies, Teesside University, Middlesbrough, United Kingdom
Abstract
Deep learning is one of the most advanced forms of machine learning. Most modern deep learning models are based on an artificial neural network, and benchmarking studies reveal that neural networks have produced results comparable to and in some cases superior to human experts. However, the generated neural networks are typically regarded as incomprehensible black-box models, which not only limits their applications, but also hinders testing and verifying. In this paper, we present an active learning framework to extract automata from neural network classifiers, which can help users to understand the classifiers. In more detail, we use Angluin’s L* algorithm as a learner and the neural network under learning as an oracle, employing abstraction interpretation of the neural network for answering membership and equivalence queries. Our abstraction consists of value, symbol and word abstractions. The factors that may affect the abstraction are also discussed in the paper. We have implemented our approach in a prototype. To evaluate it, we have performed the prototype on a MNIST classifier and have identified that the abstraction with interval number 2 and block size 1 × 28 offers the best performance in terms of F1 score. We also have compared our extracted DFA against the DFAs learned via the passive learning algorithms provided in LearnLib and the experimental results show that our DFA gives a better performance on the MNIST dataset.
Funder
National Natural Science Foundation of China
Guangdong Basic and Applied Basic Research Foundation
Reference30 articles.
1. Using MDL for grammar induction;Adriaans,2006
2. Model learning and model-based testing;Aichernig;Machine Learning for Dynamic Software Analysis: Potentials and Limits,2018
3. Learning regular sets from queries and counterexamples;Angluin;Information and Computation,1987
4. Evasion attacks against machine learning at test time;Biggio,2013
5. State automata extraction from recurrent neural nets using k-means and fuzzy clustering;Cechin,2003
Cited by
3 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献